tqchen opened a new pull request, #619:
URL: https://github.com/apache/tvm-ffi/pull/619

   The object-graph deserializer (`FromJSONGraph`) trusted several values
   taken directly from the input JSON, which let a malformed or adversarial
   graph trigger out-of-bounds reads, a stack overflow, or a segfault
   instead of a clean error.
   
   ## Changes (`src/ffi/extra/serialization.cc`)
   
   - Validate every node index (`root_index` and all child/key/value/field
     references) against the nodes array before indexing into the
     `decoded_nodes_` `std::vector`. Previously a negative index segfaulted
     in `GetOrDecodeNode` and an out-of-range index read past the vector end.
   - Add a recursion-depth guard so a deeply nested graph or a long chain of
     node references throws rather than overflowing the C++ stack; this also
     makes a self-referential node terminate by throwing.
   - Require `Device` data to be exactly `[device_type, device_id]`.
   - Require `Map`/`Dict` data to have an even number of `[key, value]`
     entries so the inner loop cannot read one element past the end.
   
   All previously-trusted indices, sizes, kinds and keys now throw an
   `ffi::Error` (`ValueError` / `TypeError` / `KeyError` / `IndexError`)
   before any unsafe access. Type-key, missing-key, and wrong-value-type
   cases were already routed through checked accessors and continue to throw.
   
   ## Tests
   
   - `tests/cpp/extra/test_serialization.cc`: a battery of crafted malformed
     graphs (out-of-range / negative indices, odd-length map data, wrong
     device arity, unknown type keys, missing keys, wrong value types,
     non-object nodes, truncated JSON, deeply nested input, self-cycle), each
     asserted to throw. The C++ test target builds with AddressSanitizer and
     the full suite passes clean; the prior unhardened code segfaults on the
     negative-index case under the same build.
   - `tests/python/test_serialization.py`: the same cases at the Python
     boundary, each asserted to raise.


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]


---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to